Facebook users warned about dangers of being app happy
Last Updated: Thursday, March 5, 2009 | 12:02 PM ET
CBC News
Related
Internal Links
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
Facebook users are being urged to be wary about what Facebook applications they accept and what links they click as cyber criminals increasingly target the popular social networking site.
In the past week, several new variants of the Koobface worm, which targets Facebook users, and a number of "rogue applications" have been reported on the site, the internet security firm Trend Micro reported.
As of Tuesday afternoon, Facebook had not returned interview requests from CBCNews.ca.
However, both Trend Micro and Facebook are urging people to take care when they use the site, which contains reams of valuable personal information about the site's 175 million users, including, in some cases, their birthdate, their favourite movies and photos from their latest vacation. Criminals gain access to that information by stealing a user's Facebook login using malicious code such as worms or rogue applications.
Facebook's current popularity makes it increasingly attractive to criminals, said Jamz Yaneza, threat researcher at Trend Micro.
"You will normally target the biggest animal on the block," he said. "I personally think they are targeting Facebook more."
He said attacks in the past had been targeted at sites such as MySpace that were more popular at the time, but attacks on Facebook began gaining six months ago.
"It's ramped up from then," he said, adding that the attacks have increased in number, types and sophistication.
On Facebook, users can install applications that allow them to play videos or online games, send each other "gifts" or share reviews of movies, books and music. Such applications can be made by programmers using a set of tools supplied by Facebook.
No mandatory screening for apps
Recently, including over the weekend, malicious applications pretending to be warnings from Facebook have cropped up on the site.
For example, one says a friend has reported them for violating Facebook's terms of service and urges them to ask Facebook to look into what has happened by clicking on a link. If the user does so, he provides the application with access to his profile. However, Facebook has said that no application, legitimate or rogue, can ever gain access to sensitive information such as a user's contact information.
Yaneza acknowledged that Facebook dealt with the latest rogue application quickly. He added that the site recently began a program to verify the safety of applications.
"The problem is it's opt in," he said.
Facebook's development tools will be open to abuse until the site requires all application developers to take part, he added.
"I think that's what needs to be done," Yaneza said.
Even if screening begins, it won't stop worms like Koobface, which masquerades as someone on the user's contact list and sends an email asking them to click on a link to a video or other content. That brings the user to an external site, where the user inadvertently downloads the worm. The program sends saved login information for Facebook and other social networking sites from the user's browser to another site, allowing the site to log in as the user.
Facebook posts descriptions of threats
Facebook keeps a page with security tips for users. It is constantly updated with descriptions of threats, as well as information about what to do if an account has been compromised. On Monday, the site posted a new photo of a third type of threat — sites that pretend to be Facebook and lure users into entering login information.
Both Trend Micro and Facebook say the number of Facebook users affected by such security issues is small at the moment, but both have provided tips to help users keep their profiles safe.
Here are some of their suggestions:
- Be judicious about installing applications. David Perry, global director of education for Trend Micro, said the safest is not to install any. "I don't throw snowballs... I don't have an aquarium. I don't do any of those things."
- When you do install an app, check its reputation first. Check Facebook's application list and scan the reviews, said Yaneza. "Read before you install. Look before you leap."
- If a link or message seems weird, don't click on it. If it seems to be from a friend, let them know, as someone may be pretending to be them, Facebook says.
- Make sure information you post on Facebook isn't something that could be used to verify your identity. Perry said users should be careful what they reveal in a popular Facebook game in which they share 25 random facts about themselves with their friends. "Don't give away your mother's maiden name or your pet's name or anything you would use as a personal question," he said, adding those are becoming increasingly valuable.
- Add a security question to your account. That way, you can prove your identity to Facebook if your account gets stolen, the site says.
- Report spam or abuse you see on discussion boards and walls. Facebook provides links that allow you to report such problems.
- Watch out for sites that imitate Facebook. Don't enter your password unless you're sure you're entering it on the real Facebook site.
- Guard your password. Don't use the same password on Facebook that you use on other sites, and don't share the password with anyone.
- Don't use Facebook? Create a profile anyway. That will help discourage other people from masquerading as you, Yaneza said.
Share Tools
Top News Headlines
- Aylmer triple stabbing leads to first-degree murder charges

- The estranged partner of a young mother who was stabbed to death along with her parents at their home in Aylmer, Que., has been charged with first-degree murder Friday. more »
- Wildfires, high winds put northeastern Ontario on alert
- It's going to be a tense weekend in northeastern Ontario where strong, shifting winds have been fuelling a forest fire that has blanketed the Timmins area with smoke and ash. more »
- Labrador fire out of control
- A forest fire continues to burn out of control in Happy Valley-Goose Bay today, according to provincial firefighting officials. more »
- The risks and responsibilities of taking on Mt. Everest

- The deaths of five climbers last weekend on Mt. Everest, with more summits underway this weekend, fuels the debate about the risks and responsibilities of high altitude climbing. more »
Latest Technology & Science News Headlines
- Unloading of docked SpaceX capsule to start Saturday
- The privately bankrolled SpaceX Dragon capsule made a historic arrival at the International Space Station on Friday, and astronauts will begin unloading some of the 544 kilograms of food, water, clothing and other supplies its carrying starting Saturday.
more »
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Aylmer triple stabbing leads to first-degree murder charges
- Everest victim's husband says family not seeking government help
- B.C. premier unhappy with disgraced Mountie's transfer
- Canada ending 'Buffalo shuffle' for visas, closing consulate
- What a Greek euro exit could mean for Canada
- Third B.C. salmon farm quarantined
- RCMP officer charged in fatal crash
- Police probe Halifax homicide after shooting
- Ottawa man in hospital after lightning strike

